CVE-2026-1359Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-11); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-11: 2Mentions · 2026-07-13: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-13: 107-1107-13
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-112
Disclosure2
2026-07-131
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH severity CVE-2026-1359 (CVSS 8.8) Genolve AI plugin for WordPress allows authenticated attackers (Contributor+) to escalate privileges to admin via missing capability check. Affected: All versions ≤5.0.5 Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/skrUPz4WZ0

    Post summary

    The tweet announces the high‑severity CVE‑2026‑1359 affecting Genolve AI WordPress plugin, explains a privilege‑escalation flaw, and urges users to apply the available patch immediately.

    0000045
    71 followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-1359](https://plugins.trac.wordpress.org/changeset?reponame=&new=3460465%40genolve-tool... https://plugins.trac.wordpress.org/changeset?reponame=&new=3460465%40genolve-toolkit&old=3432371%40genolve-toolkit #Vulnerability #CVE #ZeroDay

    Post summary

    The tweet announces CVE-2026-1359 as a zero‑day vulnerability, linking to a WordPress plugin changeset for context, but it does not provide exploitation details, patches, or technical specifics.

    0000035
    10 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1359 The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setO… https://www.cve.org/CVERecord?id=CVE-2026-1359

    Post summary

    The post announces CVE-2026-1359, describing a missing capability check in the Genolve WordPress plugin that allows unauthorized data modification.

    00000780
    57.8K followersView on X

Explore more